{"id":"DEBIAN-CVE-2018-3620","details":"Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access via a terminal page fault and a side-channel analysis.","modified":"2026-09-01T20:03:59.015309493Z","published":"2018-08-14T19:29:00.793Z","upstream":["CVE-2018-3620"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2018-3620"}],"affected":[{"package":{"name":"intel-microcode","ecosystem":"Debian:12","purl":"pkg:deb/debian/intel-microcode?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.20180703.1"}]}],"versions":["0.20080131-1","0.20080220-1","0.20080401-1","0.20080910-1","0.20080910-2","0.20090330-1","0.20090927-1","0.20100826-1","0.20100914-1","0.20101123-1","0.20110428-1","0.20110915-1","0.20111110-1","0.20120606-1","1.20120606.1","1.20120606.2","1.20120606.3","1.20120606.4","1.20120606.5","1.20120606.6","1.20120606.6~bpo60+1","1.20120606.v2.1","1.20120606.v2.2","1.20120606.v2.2~bpo60+1","1.20130222.1","1.20130222.1~bpo60+1","1.20130222.3","1.20130222.4","1.20130222.5","1.20130222.6","1.20130808.1","1.20130808.2","1.20130906.1","1.20140122.1","1.20140122.1~bpo60+1","1.20140430.1","1.20140430.1~bpo60+1","1.20140624.1","1.20140624.1~bpo60+1","1.20140913.1","1.20140913.1~bpo60+1","1.20150121.1","2.20130808.1","2.20130808.1~bpo70+1","2.20130906.1","2.20130906.1~bpo70+1","2.20140122.1","2.20140122.1~bpo70+1","2.20140430.1","2.20140430.1~bpo70+1","2.20140624.1","2.20140624.1~bpo70+1","3.20140913.1","3.20140913.1~bpo70+1","3.20140913.1~bpo70+2","3.20150107.1","3.20150107.1~bpo70+1","3.20150121.1","3.20150121.1~bpo70+1","3.20151106.1","3.20151106.1~bpo7+1","3.20151106.1~bpo8+1","3.20151106.1~deb8u1","3.20151106.2","3.20160607.1","3.20160607.2","3.20160607.2~bpo8+1","3.20160714.1","3.20160714.1~bpo8+1","3.20160714.1~deb8u1","3.20160714.1~deb8u1~bpo7+1","3.20161104.1","3.20161104.1~bpo8+1","3.20161104.1~deb8u1","3.20161104.1~deb8u1~bpo7+1","3.20170511.1","3.20170511.1~bpo8+1","3.20170707.1","3.20170707.1~bpo8+1","3.20170707.1~bpo9+1","3.20170707.1~deb8u1","3.20170707.1~deb9u1","3.20171117.1","3.20171117.1~bpo8+1","3.20171117.1~bpo9+1","3.20171215.1","3.20180108.1","3.20180108.1+really20171117.1","3.20180312.1","3.20180312.1~bpo8+1","3.20180312.1~bpo9+1","3.20180425.1","3.20180425.1~bpo8+1","3.20180425.1~bpo9+1","3.20180425.1~deb8u1","3.20180425.1~deb9u1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-3620.json"}},{"package":{"name":"intel-microcode","ecosystem":"Debian:13","purl":"pkg:deb/debian/intel-microcode?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.20180703.1"}]}],"versions":["0.20080131-1","0.20080220-1","0.20080401-1","0.20080910-1","0.20080910-2","0.20090330-1","0.20090927-1","0.20100826-1","0.20100914-1","0.20101123-1","0.20110428-1","0.20110915-1","0.20111110-1","0.20120606-1","1.20120606.1","1.20120606.2","1.20120606.3","1.20120606.4","1.20120606.5","1.20120606.6","1.20120606.6~bpo60+1","1.20120606.v2.1","1.20120606.v2.2","1.20120606.v2.2~bpo60+1","1.20130222.1","1.20130222.1~bpo60+1","1.20130222.3","1.20130222.4","1.20130222.5","1.20130222.6","1.20130808.1","1.20130808.2","1.20130906.1","1.20140122.1","1.20140122.1~bpo60+1","1.20140430.1","1.20140430.1~bpo60+1","1.20140624.1","1.20140624.1~bpo60+1","1.20140913.1","1.20140913.1~bpo60+1","1.20150121.1","2.20130808.1","2.20130808.1~bpo70+1","2.20130906.1","2.20130906.1~bpo70+1","2.20140122.1","2.20140122.1~bpo70+1","2.20140430.1","2.20140430.1~bpo70+1","2.20140624.1","2.20140624.1~bpo70+1","3.20140913.1","3.20140913.1~bpo70+1","3.20140913.1~bpo70+2","3.20150107.1","3.20150107.1~bpo70+1","3.20150121.1","3.20150121.1~bpo70+1","3.20151106.1","3.20151106.1~bpo7+1","3.20151106.1~bpo8+1","3.20151106.1~deb8u1","3.20151106.2","3.20160607.1","3.20160607.2","3.20160607.2~bpo8+1","3.20160714.1","3.20160714.1~bpo8+1","3.20160714.1~deb8u1","3.20160714.1~deb8u1~bpo7+1","3.20161104.1","3.20161104.1~bpo8+1","3.20161104.1~deb8u1","3.20161104.1~deb8u1~bpo7+1","3.20170511.1","3.20170511.1~bpo8+1","3.20170707.1","3.20170707.1~bpo8+1","3.20170707.1~bpo9+1","3.20170707.1~deb8u1","3.20170707.1~deb9u1","3.20171117.1","3.20171117.1~bpo8+1","3.20171117.1~bpo9+1","3.20171215.1","3.20180108.1","3.20180108.1+really20171117.1","3.20180312.1","3.20180312.1~bpo8+1","3.20180312.1~bpo9+1","3.20180425.1","3.20180425.1~bpo8+1","3.20180425.1~bpo9+1","3.20180425.1~deb8u1","3.20180425.1~deb9u1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-3620.json"}},{"package":{"name":"intel-microcode","ecosystem":"Debian:14","purl":"pkg:deb/debian/intel-microcode?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.20180703.1"}]}],"versions":["0.20080131-1","0.20080220-1","0.20080401-1","0.20080910-1","0.20080910-2","0.20090330-1","0.20090927-1","0.20100826-1","0.20100914-1","0.20101123-1","0.20110428-1","0.20110915-1","0.20111110-1","0.20120606-1","1.20120606.1","1.20120606.2","1.20120606.3","1.20120606.4","1.20120606.5","1.20120606.6","1.20120606.6~bpo60+1","1.20120606.v2.1","1.20120606.v2.2","1.20120606.v2.2~bpo60+1","1.20130222.1","1.20130222.1~bpo60+1","1.20130222.3","1.20130222.4","1.20130222.5","1.20130222.6","1.20130808.1","1.20130808.2","1.20130906.1","1.20140122.1","1.20140122.1~bpo60+1","1.20140430.1","1.20140430.1~bpo60+1","1.20140624.1","1.20140624.1~bpo60+1","1.20140913.1","1.20140913.1~bpo60+1","1.20150121.1","2.20130808.1","2.20130808.1~bpo70+1","2.20130906.1","2.20130906.1~bpo70+1","2.20140122.1","2.20140122.1~bpo70+1","2.20140430.1","2.20140430.1~bpo70+1","2.20140624.1","2.20140624.1~bpo70+1","3.20140913.1","3.20140913.1~bpo70+1","3.20140913.1~bpo70+2","3.20150107.1","3.20150107.1~bpo70+1","3.20150121.1","3.20150121.1~bpo70+1","3.20151106.1","3.20151106.1~bpo7+1","3.20151106.1~bpo8+1","3.20151106.1~deb8u1","3.20151106.2","3.20160607.1","3.20160607.2","3.20160607.2~bpo8+1","3.20160714.1","3.20160714.1~bpo8+1","3.20160714.1~deb8u1","3.20160714.1~deb8u1~bpo7+1","3.20161104.1","3.20161104.1~bpo8+1","3.20161104.1~deb8u1","3.20161104.1~deb8u1~bpo7+1","3.20170511.1","3.20170511.1~bpo8+1","3.20170707.1","3.20170707.1~bpo8+1","3.20170707.1~bpo9+1","3.20170707.1~deb8u1","3.20170707.1~deb9u1","3.20171117.1","3.20171117.1~bpo8+1","3.20171117.1~bpo9+1","3.20171215.1","3.20180108.1","3.20180108.1+really20171117.1","3.20180312.1","3.20180312.1~bpo8+1","3.20180312.1~bpo9+1","3.20180425.1","3.20180425.1~bpo8+1","3.20180425.1~bpo9+1","3.20180425.1~deb8u1","3.20180425.1~deb9u1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-3620.json"}},{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.17.15-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-3620.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.17.15-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-3620.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.17.15-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-3620.json"}},{"package":{"name":"xen","ecosystem":"Debian:12","purl":"pkg:deb/debian/xen?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.11.1~pre.20180911.5acdd26fdc+dfsg-2"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-3620.json"}},{"package":{"name":"xen","ecosystem":"Debian:13","purl":"pkg:deb/debian/xen?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.11.1~pre.20180911.5acdd26fdc+dfsg-2"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-3620.json"}},{"package":{"name":"xen","ecosystem":"Debian:14","purl":"pkg:deb/debian/xen?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.11.1~pre.20180911.5acdd26fdc+dfsg-2"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2018-3620.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N"}]}